External risk intelligence

Oracle Coherence Core Vulnerability Allows Unauthenticated Network Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60225

Oracle Coherence is a data grid solution typically deployed in backend, internal-facing environments to manage application data. While the vulnerability is reachable via HTTP, these components are generally located behind application tiers or within private networks rather than being directly exposed to the public internet.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Coherence, a component within Oracle Fusion Middleware. This issue, if exploited, could allow an unauthorized attacker to gain complete control over the affected Coherence systems. The potential impact on business operations is significant due to the high severity score and the nature of the compromise.

  • Unauthenticated attackers can take over Coherence.
  • Matters due to potential full system compromise.
  • Confirm relevance and exposure to business operations.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker with network access via HTTP can target the Core component of Oracle Coherence. Exploiting this vulnerability could lead to a complete takeover of the Oracle Coherence system, impacting confidentiality, integrity, and availability.

  • Network access required.
  • Core component is vulnerable.
  • Full system takeover is possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker with network access via HTTP to take over Oracle Coherence. This could impact the confidentiality, integrity, and availability of the system when supported by the advisory.

  • Oracle Coherence system data.
  • Network access via HTTP.
  • Complete takeover of Oracle Coherence.

Operational Fix

Recommended remediation, mitigation, and detection steps

Platform and infrastructure teams are likely responsible for addressing this vulnerability in Oracle Coherence, given its role as a data grid solution typically deployed in backend environments. The immediate first step is to identify all instances of the affected technology, confirm their network reachability and business criticality, and then assign ownership to the appropriate team for risk-based remediation planning.

  • Platform and infrastructure teams own the issue.
  • Verify network reachability and business criticality.
  • Plan remediation and vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Coherence?

Oracle Coherence is a distributed data grid solution that serves as an in-memory data management layer. It is used by applications to cache data, handle high-volume transactions, and improve performance by storing information across multiple servers within a cluster.

What does CVE-2026-60225 mean for system security?

This vulnerability represents a critical flaw in the Core component of Oracle Coherence. It allows an attacker to bypass authentication mechanisms entirely, potentially gaining complete control over the system, which affects the security, integrity, and availability of stored data.

How can an attacker trigger this vulnerability?

An attacker needs network access to the target system via HTTP to initiate an attack. Notably, this flaw does not require the attacker to have pre-existing credentials or user privileges on the system to attempt the compromise.

Do I need to worry if my Oracle Coherence instance is internal?

Halo Surface Signal indicates that while this flaw is reachable via HTTP, Oracle Coherence is typically used in backend environments behind application tiers. If your deployment is restricted to a private, non-public network, the immediate risk may be lower compared to services directly exposed to the internet.

What should I do first to address this vulnerability?

Begin by auditing your infrastructure to locate all instances of Oracle Coherence. Once identified, evaluate their network accessibility and business importance to prioritize them for remediation, then coordinate with the teams managing those specific systems.

References